SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the filesystem.renamer()
function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd 3.2.1RC1. As a workaround, limit downloads to NZBs without PAR2 files, deny write permissions to the SABnzbd process outside areas it must access to perform its job, or update to a fixed version.
CPE | Name | Operator | Version |
---|---|---|---|
sabnzbd | eq | 0.7.6Beta2 | |
sabnzbd | eq | 2.3.4 | |
sabnzbd | eq | 2.2.0RC1 | |
sabnzbd | eq | 0.7.11RC1 | |
sabnzbd | eq | 1.2.1 | |
sabnzbd | eq | 0.7.0Alpha3 | |
sabnzbd | eq | 0.7.0Beta4 | |
sabnzbd | eq | 0.8.0Beta3 | |
sabnzbd | eq | 2.3.8RC1 | |
sabnzbd | eq | 2.3.0RC2 |